# Beats

**URL:** https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=71

[Latest](https://discuss.elastic.co/latest.md) · [Categories](https://discuss.elastic.co/categories.md) · [Tags](https://discuss.elastic.co/tags.md)

**Page:** 72

---

## [Reading json array with filebeat](https://discuss.elastic.co/t/reading-json-array-with-filebeat/317090)

<div class="topic-metadata">

**Author:** [@Steve666](https://discuss.elastic.co/u/Steve666)\
**Replies:** 0\
**Last updated:** [October 20, 2022, 9:41am UTC](https://discuss.elastic.co/t/reading-json-array-with-filebeat/317090 "2022-10-20T09:41:09Z")

</div>

Hi all, Is there any possible way to extract a json array as follow with filebeat ? \</\> { "processingData" : { "tiffs" : \[ { "tiffName" : "blabla", "tiffHeight\_mm" : 1, "tiffWidth\_mm" …

---

## [Problem with filestream access denied on windows](https://discuss.elastic.co/t/problem-with-filestream-access-denied-on-windows/317086)

<div class="topic-metadata">

**Author:** [@drbytes](https://discuss.elastic.co/u/drbytes)\
**Replies:** 0\
**Last updated:** [October 20, 2022, 9:06am UTC](https://discuss.elastic.co/t/problem-with-filestream-access-denied-on-windows/317086 "2022-10-20T09:06:48Z")

</div>

Hello I'm running into a problem with filebeat, an access denied. I have a directory located on c:\\DIR1\\DIR2\\LOG\_DIR, LOG\_DIR contains the log files which are read by filebeat using a filestream glob. The user running f…

---

## [Filebeat monitoring metrics not visible in ElasticSearch](https://discuss.elastic.co/t/filebeat-monitoring-metrics-not-visible-in-elasticsearch/315596)

<div class="topic-metadata">

**Author:** [@ppine7](https://discuss.elastic.co/u/ppine7)\
**Replies:** 31\
**Last updated:** [October 20, 2022, 2:41am UTC](https://discuss.elastic.co/t/filebeat-monitoring-metrics-not-visible-in-elasticsearch/315596 "2022-10-20T02:41:58Z")

</div>

Hi, I have posted this question on SO but could not get a good answer yet .... Basically I think I have configured Fielbeat + ES according to the docs , to send Filebeat monitored metrics into ES - but nothing is showin…

---

## [Filebeat on macOS documentation error, breaking change](https://discuss.elastic.co/t/filebeat-on-macos-documentation-error-breaking-change/316996)

<div class="topic-metadata">

**Author:** [@maxried](https://discuss.elastic.co/u/maxried)\
**Replies:** 1\
**Last updated:** [October 19, 2022, 10:20pm UTC](https://discuss.elastic.co/t/filebeat-on-macos-documentation-error-breaking-change/316996 "2022-10-19T22:20:23Z")

</div>

Hi all, I'm running filebeat on macOS. It starts as a launchd service. After upgrading from 7 to 8, the daemon didn't run. I investigated this issue, and found that its command-line included --environment macos\_service …

---

## [Filebeat on no internet](https://discuss.elastic.co/t/filebeat-on-no-internet/317022)

<div class="topic-metadata">

**Author:** [@Virendra\_Negi](https://discuss.elastic.co/u/Virendra_Negi)\
**Replies:** 1\
**Last updated:** [October 19, 2022, 5:01pm UTC](https://discuss.elastic.co/t/filebeat-on-no-internet/317022 "2022-10-19T17:01:47Z")

</div>

We have our servers located geographically at remote places (where the internet is not as reliable) the Filebeat shipper is responsible to ship the logs to our ELK via KAFKA -\> LOGSTASH -\> ELASTIC The thing I'm unable t…

---

## [Unable to ship logs from beats to logstash](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048)

<div class="topic-metadata">

**Author:** [@charlot\_Attard](https://discuss.elastic.co/u/charlot_Attard)\
**Replies:** 24\
**Last updated:** [October 19, 2022, 1:29pm UTC](https://discuss.elastic.co/t/unable-to-ship-logs-from-beats-to-logstash/316048 "2022-10-19T13:29:48Z")

</div>

I have configured beats to ouput logs to logstash via 2 servers. The problem is that for some reason logs are not being shipped to Logstash, I even ran a tcpdump on logstash servers and can't find anything relevant. What…

---

## [Kubernetes Module of Metricbeat does not get pct metrics from Kubelet on Windows](https://discuss.elastic.co/t/kubernetes-module-of-metricbeat-does-not-get-pct-metrics-from-kubelet-on-windows/315694)

<div class="topic-metadata">

**Author:** [@rituzzzpilot](https://discuss.elastic.co/u/rituzzzpilot)\
**Replies:** 3\
**Last updated:** [October 19, 2022, 7:26am UTC](https://discuss.elastic.co/t/kubernetes-module-of-metricbeat-does-not-get-pct-metrics-from-kubelet-on-windows/315694 "2022-10-19T07:26:07Z")

</div>

Hi, everyone I have been testing metricbeat 7.17 Kubernetes module with Kubelet 1.24.3 and windows worker nodes (Windows Server 2022). I use Metricbeat in order to get metrics of containers, pods and nodes. I got node a…

---

## [Not able to monitor with Metricbeat. Monitoring with Self monitoring in kibana](https://discuss.elastic.co/t/not-able-to-monitor-with-metricbeat-monitoring-with-self-monitoring-in-kibana/316790)

<div class="topic-metadata">

**Author:** [@Rakhshunda\_Noorein\_J](https://discuss.elastic.co/u/Rakhshunda_Noorein_J)\
**Replies:** 6\
**Last updated:** [October 19, 2022, 6:14am UTC](https://discuss.elastic.co/t/not-able-to-monitor-with-metricbeat-monitoring-with-self-monitoring-in-kibana/316790 "2022-10-19T06:14:30Z")

</div>

Hello, I have configured metricbeat in windows providing you the steps I followed. kibana -\> stack monitoring -\> monitor with metricbeat -\> followed the steps mentioned there -\> downloaded and setup metricbeat. -\> cha…

---

## [About zabbix and elastic](https://discuss.elastic.co/t/about-zabbix-and-elastic/316946)

<div class="topic-metadata">

**Author:** [@sjh0207](https://discuss.elastic.co/u/sjh0207)\
**Replies:** 1\
**Last updated:** [October 19, 2022, 3:20am UTC](https://discuss.elastic.co/t/about-zabbix-and-elastic/316946 "2022-10-19T03:20:35Z")

</div>

Hi. i'm from korea Please understand that I am using a translator due to lack of English skills I am considering zabbix and elastic for network traffic monitoring. The reason for considering zabbix and elastic is to …

---

## [Okta log Intergration](https://discuss.elastic.co/t/okta-log-intergration/316830)

<div class="topic-metadata">

**Author:** [@sean.doody](https://discuss.elastic.co/u/sean.doody)\
**Replies:** 3\
**Last updated:** [October 19, 2022, 3:18am UTC](https://discuss.elastic.co/t/okta-log-intergration/316830 "2022-10-19T03:18:26Z")

</div>

Hello, I am trying to test getting Okta logs to Elastic, when trying to do so, it doesnt seem like Elastic wants to ingest the logs. I am currently just testing off a work laptop, but one I get this figured out I will us…

---

## [Agent binary download source location not working](https://discuss.elastic.co/t/agent-binary-download-source-location-not-working/316925)

<div class="topic-metadata">

**Author:** [@andrisarkameru](https://discuss.elastic.co/u/andrisarkameru)\
**Replies:** 0\
**Last updated:** [October 18, 2022, 5:09pm UTC](https://discuss.elastic.co/t/agent-binary-download-source-location-not-working/316925 "2022-10-18T17:09:40Z")

</div>

Hello, I'm using elasticsearch/kibana version 8.4.2 on windows containers. It seems that Kibana fleet binary download source setting does not work, or does not get taken into account. i'm following the air-gapped inst…

---

## [Winlogbeat SSL connection to ES\\Kibana](https://discuss.elastic.co/t/winlogbeat-ssl-connection-to-es-kibana/316645)

<div class="topic-metadata">

**Author:** [@EExisT](https://discuss.elastic.co/u/EExisT)\
**Replies:** 4\
**Last updated:** [October 18, 2022, 3:27pm UTC](https://discuss.elastic.co/t/winlogbeat-ssl-connection-to-es-kibana/316645 "2022-10-18T15:27:38Z")

</div>

Hello, i have an Ubuntu VM where I run ES and Kibana and a Windows VM where i want to run Winlogbeat. The idea is to send windows events to ES and visualise it with Kibana. Kibana is reachable by browser from both VMs…

---

## [The result of "metricbeat test modules sql" has timeout failure when the query does not have any output](https://discuss.elastic.co/t/the-result-of-metricbeat-test-modules-sql-has-timeout-failure-when-the-query-does-not-have-any-output/316874)

<div class="topic-metadata">

**Author:** [@donald\_b90](https://discuss.elastic.co/u/donald_b90)\
**Replies:** 1\
**Last updated:** [October 18, 2022, 3:01pm UTC](https://discuss.elastic.co/t/the-result-of-metricbeat-test-modules-sql-has-timeout-failure-when-the-query-does-not-have-any-output/316874 "2022-10-18T15:01:32Z")

</div>

Hi All, First of all, I appreciate your attention in advance. Since, I am new in using ELK Stack, I have one question. I have one simple query in my sql.yml file which returns no records (The sql module is enabled). /…

---

## [Create indexes from previous nginx access logs](https://discuss.elastic.co/t/create-indexes-from-previous-nginx-access-logs/316818)

<div class="topic-metadata">

**Author:** [@kosmylo](https://discuss.elastic.co/u/kosmylo)\
**Replies:** 3\
**Last updated:** [October 18, 2022, 5:21am UTC](https://discuss.elastic.co/t/create-indexes-from-previous-nginx-access-logs/316818 "2022-10-18T05:21:59Z")

</div>

I use filebeat to send nginx access logs to logstash to parse them and then to elasticsearch. The folder includes access logs my previous days, but when I deploy the ELK stack, only the newly arrived nginx access logs ar…

---

## [ERROR checkpoint/checkpoint.go:200](https://discuss.elastic.co/t/error-checkpoint-checkpoint-go-200/316644)

<div class="topic-metadata">

**Author:** [@lsbitri88](https://discuss.elastic.co/u/lsbitri88)\
**Replies:** 4\
**Last updated:** [October 17, 2022, 5:45pm UTC](https://discuss.elastic.co/t/error-checkpoint-checkpoint-go-200/316644 "2022-10-17T17:45:40Z")

</div>

Hi all, trying to find out what is the root cause of this error : // ERROR checkpoint/checkpoint.go:200 rename X:\\Directory\\winlogbeat\\data.winlogbeat.yml.new X:\\Directory\\winlogbeat\\data.winlogbeat.yml: Access is den…

---

## [Filebeat unable to ship logs to Logstash](https://discuss.elastic.co/t/filebeat-unable-to-ship-logs-to-logstash/316802)

<div class="topic-metadata">

**Author:** [@charlot\_Attard](https://discuss.elastic.co/u/charlot_Attard)\
**Replies:** 1\
**Last updated:** [October 17, 2022, 3:05pm UTC](https://discuss.elastic.co/t/filebeat-unable-to-ship-logs-to-logstash/316802 "2022-10-17T15:05:52Z")

</div>

Dear all, I am encountering a strange issue. I am configuring filebeat on a windows server forwarding logs to logstash on a linux server. Network access is reachable. When configuring filebeat agents to connect to logst…

---

## [Kubernetes Filebeat autodiscover does not find containers](https://discuss.elastic.co/t/kubernetes-filebeat-autodiscover-does-not-find-containers/316713)

<div class="topic-metadata">

**Author:** [@akiks](https://discuss.elastic.co/u/akiks)\
**Replies:** 0\
**Last updated:** [October 16, 2022, 9:17pm UTC](https://discuss.elastic.co/t/kubernetes-filebeat-autodiscover-does-not-find-containers/316713 "2022-10-16T21:17:53Z")

</div>

I'm trying to let filebeat collect logs of containers running within Kubernetes using a conditional autodiscover template, but filebeat does never print any of the containers logs. Here is an example container whose lo…

---

## [Heartbeat auto discovery generates second monitor which is always down](https://discuss.elastic.co/t/heartbeat-auto-discovery-generates-second-monitor-which-is-always-down/315491)

<div class="topic-metadata">

**Author:** [@kintetsu](https://discuss.elastic.co/u/kintetsu)\
**Replies:** 12\
**Last updated:** [October 17, 2022, 10:29am UTC](https://discuss.elastic.co/t/heartbeat-auto-discovery-generates-second-monitor-which-is-always-down/315491 "2022-10-17T10:29:04Z")

</div>

Hi, since we updated Heartbeat in our Kubernetes cluster from version 7.17.x to 8.3.3, we have a second monitor for every pod we have annotated. Both monitors have the same name and the same tags. Just one has no UR…

---

## [Filebeat ignore all pattern](https://discuss.elastic.co/t/filebeat-ignore-all-pattern/316705)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 2\
**Last updated:** [October 17, 2022, 2:04am UTC](https://discuss.elastic.co/t/filebeat-ignore-all-pattern/316705 "2022-10-17T02:04:42Z")

</div>

i used simple config parsers: - multiline: type: pattern pattern: '^test' negate: false match: after output.console: pretty: true ter\_id":"41e9015a-67cd-4e5a-b602-6ce8a0eba50d","ecs.version":"1.6…

---

## [👀 Host.network.ingress.bytes looks broken](https://discuss.elastic.co/t/host-network-ingress-bytes-looks-broken/316696)

<div class="topic-metadata">

**Author:** [@Its\_Anton](https://discuss.elastic.co/u/Its_Anton)\
**Replies:** 4\
**Last updated:** [October 15, 2022, 10:17pm UTC](https://discuss.elastic.co/t/host-network-ingress-bytes-looks-broken/316696 "2022-10-15T22:17:57Z")

</div>

Hi! I have a Docker Swarm cluster with 4 nodes and Metricbeat installed on every node as a global service. According to docs: host.network.ingress.bytes The number of bytes received (gauge) on all network interfaces …

---

## [Filebeat bugs not respect pattern go](https://discuss.elastic.co/t/filebeat-bugs-not-respect-pattern-go/316695)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 0\
**Last updated:** [October 15, 2022, 7:18pm UTC](https://discuss.elastic.co/t/filebeat-bugs-not-respect-pattern-go/316695 "2022-10-15T19:18:51Z")

</div>

i ve used this filebeat.inputs: - type: log enabled: true paths: - G:\\\\logs\\\\test\\\\\*.\* parsers: - multiline: type: pattern pattern: '^\\d{4}-\\d{2}-\\d{2}' negate: true m…

---

## [Invalid protocol when filebeat send to logstash](https://discuss.elastic.co/t/invalid-protocol-when-filebeat-send-to-logstash/316681)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 16\
**Last updated:** [October 15, 2022, 2:07pm UTC](https://discuss.elastic.co/t/invalid-protocol-when-filebeat-send-to-logstash/316681 "2022-10-15T14:07:06Z")

</div>

\[2022-10-15T11:01:12,651\]\[INFO \]\[org.logstash.beats.BeatsHandler\]\[terza\]\[7bd5f0adbbfa46b9e9ef1e064135c6f8c54b821b69f260da353a735193b5fe7d\] \[local: 172.19.1.12:5044, remote: 172.19.0.1:53380\] Handling exception: io.netty.…

---

## [Filebeat error when setting index name](https://discuss.elastic.co/t/filebeat-error-when-setting-index-name/316680)

<div class="topic-metadata">

**Author:** [@Nikolas1306](https://discuss.elastic.co/u/Nikolas1306)\
**Replies:** 0\
**Last updated:** [October 15, 2022, 10:44am UTC](https://discuss.elastic.co/t/filebeat-error-when-setting-index-name/316680 "2022-10-15T10:44:37Z")

</div>

filebeat.inputs: - type: log enabled: true paths: - /FSEBroker\\\*.\* output.elasticsearch: hosts: \[ "http://172.19.1.12:9200"\] protocol: "http" index: "fss2-%{+yyyy.MM.dd}" log error G:\\\>G…

---

## [Elastic-agent: Error dialing x509: certificate signed by unknown authority](https://discuss.elastic.co/t/elastic-agent-error-dialing-x509-certificate-signed-by-unknown-authority/315675)

<div class="topic-metadata">

**Author:** [@enigmatic](https://discuss.elastic.co/u/enigmatic)\
**Replies:** 5\
**Last updated:** [October 14, 2022, 12:41pm UTC](https://discuss.elastic.co/t/elastic-agent-error-dialing-x509-certificate-signed-by-unknown-authority/315675 "2022-10-14T12:41:41Z")

</div>

Hi All, Hope you can help wit the following. I installed Elasticsearch and Kibana version 8.4. both are up and running. I'm trying to install Fleet to manage the elastic-agents, how ever i hit a road block. the elast…

---

## [Functionbeat fails to update with a new cloudwatch log group Could not execute the lambda function](https://discuss.elastic.co/t/functionbeat-fails-to-update-with-a-new-cloudwatch-log-group-could-not-execute-the-lambda-function/315020)

<div class="topic-metadata">

**Author:** [@Kay\_Khan](https://discuss.elastic.co/u/Kay_Khan)\
**Replies:** 1\
**Last updated:** [October 14, 2022, 7:07am UTC](https://discuss.elastic.co/t/functionbeat-fails-to-update-with-a-new-cloudwatch-log-group-could-not-execute-the-lambda-function/315020 "2022-10-14T07:07:16Z")

</div>

We had functionbeat running and i had to remove and recreate it, however im getting the following errors: {"log.level":"info","@timestamp":"2022-09-23T13:55:44.066+0100","log.logger":"aws","log.origin":{"file.name":"aws…

---

## [Filebeats, unable to read all the data from log file](https://discuss.elastic.co/t/filebeats-unable-to-read-all-the-data-from-log-file/316102)

<div class="topic-metadata">

**Author:** [@adityak248](https://discuss.elastic.co/u/adityak248)\
**Replies:** 8\
**Last updated:** [October 13, 2022, 6:17pm UTC](https://discuss.elastic.co/t/filebeats-unable-to-read-all-the-data-from-log-file/316102 "2022-10-13T18:17:30Z")

</div>

Hello Team, Greetings, I am trying to ingest data from log file to elastic via logstash. Here is the pipeline -\> LOG\_FILE \> FILEBEAT \> LOGSTASH \> ELASTIC. Not sure but recently been observing the logs are missing in …

---

## [Auth.log grok parsing errors](https://discuss.elastic.co/t/auth-log-grok-parsing-errors/316547)

<div class="topic-metadata">

**Author:** [@P-T-I](https://discuss.elastic.co/u/P-T-I)\
**Replies:** 0\
**Last updated:** [October 13, 2022, 2:44pm UTC](https://discuss.elastic.co/t/auth-log-grok-parsing-errors/316547 "2022-10-13T14:44:55Z")

</div>

All my auth.log entries show up as grok errors: Provided Grok expressions do not match field value: \[{"@timestamp":"2022-10-13T13:59:21.176Z","@metadata":{"beat":"filebeat","type":"\_doc","version":"8.4.3","pipeline":"fi…

---

## [Elastic-Agent - Non-zero metrics in the last 30s](https://discuss.elastic.co/t/elastic-agent-non-zero-metrics-in-the-last-30s/302052)

<div class="topic-metadata">

**Author:** [@zx8086](https://discuss.elastic.co/u/zx8086)\
**Replies:** 1\
**Last updated:** [October 13, 2022, 11:47am UTC](https://discuss.elastic.co/t/elastic-agent-non-zero-metrics-in-the-last-30s/302052 "2022-10-13T11:47:24Z")

</div>

Running 8.1.2, is there a way to disable the metrics logging of this within the Elastic-Agent ? This without disabling "Collect Agent Logs"... I want the logs but not the metrics logging. You normally could do this …

---

## [Telegraf ingested by elastic (via metricbeat?)](https://discuss.elastic.co/t/telegraf-ingested-by-elastic-via-metricbeat/316528)

<div class="topic-metadata">

**Author:** [@A\_Mightiev](https://discuss.elastic.co/u/A_Mightiev)\
**Replies:** 0\
**Last updated:** [October 13, 2022, 11:15am UTC](https://discuss.elastic.co/t/telegraf-ingested-by-elastic-via-metricbeat/316528 "2022-10-13T11:15:04Z")

</div>

Hello, I have multiple services that have telegraf exposing the metrics of the service on port 9122 to show the metrics of what is running (sql, mongodb, etc) so basically I get the metrics by simply doing a get on SERVE…

---

## [Geo Info for Heartbeat](https://discuss.elastic.co/t/geo-info-for-heartbeat/316438)

<div class="topic-metadata">

**Author:** [@Tim\_Mobley](https://discuss.elastic.co/u/Tim_Mobley)\
**Replies:** 1\
**Last updated:** [October 13, 2022, 8:11am UTC](https://discuss.elastic.co/t/geo-info-for-heartbeat/316438 "2022-10-13T08:11:57Z")

</div>

I'm trying to set up Heartbeat so that we can use the data on a map in Kibana. What I want is one heartbeat installation to handle various geographic locations. However, the lat/long settings are in the heartbeat.yml fil…

[Previous page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=70)

[Next page](https://discuss.elastic.co/c/elastic-stack/beats/28.md?page=72)
